- Overview
- Get started
- Concepts
- Using UiPath CLI
- How-to guides
- Overview
- Pack and publish a solution
- Deploy to Orchestrator from CI
- Run tests in a pipeline
- Deploy an Agent
- Manage Orchestrator assets and queues
- Reuse existing Orchestrator resources
- CI/CD recipes
- Command reference
- Overview
- Exit codes
- Global options
- uip codedagent
- uip coder
- uip context-grounding
- uip docsai
- uip function
- uip guardrails
- uip llm-configuration
- uip llm-gateway
- uip model-hub
- add-test-data-entity
- add-test-data-queue
- add-test-data-variation
- analyze
- build
- create-project
- diff
- find-activities
- get-analyzer-rules
- get-default-activity-xaml
- get-errors
- get-manual-test-cases
- get-manual-test-steps
- get-library-object-repository
- get-object-repository
- get-versions
- get-workflow-example
- indicate-application
- indicate-element
- inspect-package
- install-data-fabric-entities
- install-or-update-packages
- list-data-fabric-entities
- list-instances
- list-workflow-examples
- pack
- publish
- remote
- restore
- run, debug & execution
- run-file
- search-templates
- start-studio
- stop-execution
- tm
- uia
- uip tasks
- uip traces
- uip traces feedback
- Migration
- Reference & support
Daily tasks for managing Orchestrator runtime resources with `uip or`, covering assets, buckets, libraries, queues, triggers, and webhooks.
uip or is the general-purpose CRUD surface over Orchestrator's runtime resources: assets, buckets (and files inside them), libraries, queues (and items), triggers, and webhooks — alongside the jobs, processes, and folders commands documented elsewhere in this guide. This page collects the tasks that come up daily — bulk-creating assets, moving files in and out of buckets, dispatching queue work, inspecting triggers — as copy-pasteable snippets.
The full flag list for every subcommand is on the uip or reference page and its per-resource pages. This page covers the common usage patterns.
uip or (this page) is different from uip solution resource. uip or always calls Orchestrator on a live tenant. uip solution resource only ever reads local resource declarations inside a .uipx solution on disk. If in doubt, look at the prefix.
Conventions you need to know first
Before any snippet works:
- Authentication. Every
uip orverb calls Orchestrator. Runuip loginfirst. Runuip login tenant set <name>to switch the active tenant before a call that targets a different one. - Folder scoping. Assets, buckets, queues, queue items, and time/queue triggers are folder-scoped — pass
--folder-path(e.g.Shared) or--folder-key(GUID), or--all-folderswhere that flag is supported. Libraries, API triggers, and webhooks are tenant-scoped and reject the folder flags. - Keys. List verbs return GUIDs (
key,identifier,uniqueKey). Pass those toget,update, anddelete. Numericidfields are internal; do not pass them to commands. - Destructive operations require
-y, --yes. Everydeleteverb on these resources refuses to run without it — the CLI never prompts interactively. - JSON is the default output. Every snippet below relies on this; see Output formats.
Assets
Bulk-deploy assets from a CSV
This is the most common "manage my secrets and config" task. Given a CSV like:
name,value,type,folderPath
ApiEndpoint,https://api.example.com,Text,Shared
MaxRetries,3,Integer,Shared
Debug,false,Bool,Shared
name,value,type,folderPath
ApiEndpoint,https://api.example.com,Text,Shared
MaxRetries,3,Integer,Shared
Debug,false,Bool,Shared
Loop over it with plain bash + uip or assets create:
#!/usr/bin/env bash
set -euo pipefail
# Skip the header row
tail -n +2 ./assets.csv | while IFS=, read -r name value type folder; do
uip or assets create "$name" "$value" \
--folder-path "$folder" \
--type "$type"
done
#!/usr/bin/env bash
set -euo pipefail
# Skip the header row
tail -n +2 ./assets.csv | while IFS=, read -r name value type folder; do
uip or assets create "$name" "$value" \
--folder-path "$folder" \
--type "$type"
done
Re-running this against the same folder will fail on duplicates. Two ways to handle that:
-
Upsert pattern. List first, then
createorupdateper row:tail -n +2 ./assets.csv | while IFS=, read -r name value type folder; do existing=$(uip or assets list --folder-path "$folder" --name "$name" \ --output-filter "Data[?name=='$name'] | [0].key" --output plain) if [ -n "$existing" ] && [ "$existing" != "null" ]; then uip or assets update "$existing" "$value" else uip or assets create "$name" "$value" --folder-path "$folder" --type "$type" fi donetail -n +2 ./assets.csv | while IFS=, read -r name value type folder; do existing=$(uip or assets list --folder-path "$folder" --name "$name" \ --output-filter "Data[?name=='$name'] | [0].key" --output plain) if [ -n "$existing" ] && [ "$existing" != "null" ]; then uip or assets update "$existing" "$value" else uip or assets create "$name" "$value" --folder-path "$folder" --type "$type" fi done -
Solution deploy pattern. For asset sets that ship alongside a package, declare them in the Solution manifest and use
uip solution deploy run --config-file— that path is idempotent by design. See How-to: pack and publish a Solution.
Credential-type assets
Credential and secret assets need a credential-store key:
# Find the credential store
STORE_KEY=$(uip or credential-stores list \
--output-filter "Data[?name=='MyStore'] | [0].key" --output plain)
# Create the credential asset (value format: username:password)
uip or assets create ApiLogin "alice:s3cr3t" \
--folder-path Shared \
--type Credential \
--credential-store-key "$STORE_KEY"
# Find the credential store
STORE_KEY=$(uip or credential-stores list \
--output-filter "Data[?name=='MyStore'] | [0].key" --output plain)
# Create the credential asset (value format: username:password)
uip or assets create ApiLogin "alice:s3cr3t" \
--folder-path Shared \
--type Credential \
--credential-store-key "$STORE_KEY"
Credential and secret values are never returned by list or get; use assets get-asset-value (which still needs a folder scope) to read the live value, or call through the robot.
Sharing assets across folders
Create once in Shared, then share to each folder that needs it:
ASSET_KEY=$(uip or assets list --folder-path Shared --name ApiEndpoint \
--output-filter "Data[0].key" --output plain)
for folder in Production Staging Development; do
uip or assets share "$ASSET_KEY" --folder-path "$folder"
done
ASSET_KEY=$(uip or assets list --folder-path Shared --name ApiEndpoint \
--output-filter "Data[0].key" --output plain)
for folder in Production Staging Development; do
uip or assets share "$ASSET_KEY" --folder-path "$folder"
done
Revoke with unshare. See Assets for the full verb list.
Buckets and bucket files
Upload a local file
BUCKET_KEY=$(uip or buckets list --folder-path Shared \
--output-filter "Data[?name=='invoices'] | [0].key" --output plain)
uip or bucket-files upload "$BUCKET_KEY" "inbox/invoice-001.pdf" \
--folder-path Shared \
--file ./invoice-001.pdf
BUCKET_KEY=$(uip or buckets list --folder-path Shared \
--output-filter "Data[?name=='invoices'] | [0].key" --output plain)
uip or bucket-files upload "$BUCKET_KEY" "inbox/invoice-001.pdf" \
--folder-path Shared \
--file ./invoice-001.pdf
The path inside the bucket (inbox/invoice-001.pdf) is the second argument to upload; --file is the local path to upload. Content type is auto-detected; pass --content-type to override.
Download a file
uip or bucket-files download "$BUCKET_KEY" "reports/summary.csv" \
--folder-path Shared \
--destination ./summary.csv
uip or bucket-files download "$BUCKET_KEY" "reports/summary.csv" \
--folder-path Shared \
--destination ./summary.csv
Without --destination, the content is streamed to stdout — useful for piping into a processor.
List and paginate
# First page
uip or bucket-files list "$BUCKET_KEY" --folder-path Shared
# The response carries a continuationToken — pass it back to fetch the next page
uip or bucket-files list "$BUCKET_KEY" --folder-path Shared \
--continuation-token "<token-from-previous-response>"
# First page
uip or bucket-files list "$BUCKET_KEY" --folder-path Shared
# The response carries a continuationToken — pass it back to fetch the next page
uip or bucket-files list "$BUCKET_KEY" --folder-path Shared \
--continuation-token "<token-from-previous-response>"
Bucket file listings are the one resource in the CLI that uses a continuation token rather than offset pagination — the other list verbs take --limit / --offset.
Pre-signed URLs
If a robot or external service needs direct blob access without going through the CLI:
uip or bucket-files get-upload-url "$BUCKET_KEY" "inbox/incoming.pdf" \
--folder-path Shared --expiry-in-minutes 30
uip or bucket-files get-download-url "$BUCKET_KEY" "reports/summary.csv" \
--folder-path Shared --expiry-in-minutes 30
uip or bucket-files get-upload-url "$BUCKET_KEY" "inbox/incoming.pdf" \
--folder-path Shared --expiry-in-minutes 30
uip or bucket-files get-download-url "$BUCKET_KEY" "reports/summary.csv" \
--folder-path Shared --expiry-in-minutes 30
Both return a time-limited URL scoped to the single file path.
Queues and queue items
Create a queue
uip or queues create InvoiceQueue \
--folder-path Shared \
--max-retries 3 \
--retention-period 90
uip or queues create InvoiceQueue \
--folder-path Shared \
--max-retries 3 \
--retention-period 90
Full flag list — --auto-retry, --enforce-unique-reference, --encrypted, retention settings — on the queues reference.
Add a single work item
uip or queue-items add InvoiceQueue \
--folder-path Shared \
--specific-content '{"InvoiceId":"INV-001","Amount":1500}' \
--priority High
uip or queue-items add InvoiceQueue \
--folder-path Shared \
--specific-content '{"InvoiceId":"INV-001","Amount":1500}' \
--priority High
--specific-content is the JSON payload the robot will read.
Bulk-add from a file
cat > ./items.json <<'EOF'
[
{"specificContent": {"InvoiceId":"INV-001"}, "priority": "Normal"},
{"specificContent": {"InvoiceId":"INV-002"}, "priority": "Normal"}
]
EOF
ITEMS=$(jq -c . ./items.json)
uip or queue-items bulk-add InvoiceQueue \
--folder-path Shared \
--queue-items "$ITEMS" \
--commit-type StopOnFirstFailure
cat > ./items.json <<'EOF'
[
{"specificContent": {"InvoiceId":"INV-001"}, "priority": "Normal"},
{"specificContent": {"InvoiceId":"INV-002"}, "priority": "Normal"}
]
EOF
ITEMS=$(jq -c . ./items.json)
uip or queue-items bulk-add InvoiceQueue \
--folder-path Shared \
--queue-items "$ITEMS" \
--commit-type StopOnFirstFailure
Each item accepts specificContent, priority, reference, deferDate, dueDate — there is no per-item queue name; the queue is the single positional argument (InvoiceQueue above) shared by the whole batch.
--commit-type controls what happens when one row fails validation: ProcessAllIndependently (default), StopOnFirstFailure, or AllOrNothing.
Inspect failed items
uip or queue-items list --folder-path Shared \
--queue-name InvoiceQueue \
--status Failed \
--output-filter "Data[].{key:uniqueKey, ref:reference, reason:processingException}"
uip or queue-items list --folder-path Shared \
--queue-name InvoiceQueue \
--status Failed \
--output-filter "Data[].{key:uniqueKey, ref:reference, reason:processingException}"
Use queue-items get-history on a single uniqueKey to see its full state transition history — useful for diagnosing retry loops.
Mark failed items for retry
uip or queue-items set-review-status Retried \
"<queue-item-key-1>" "<queue-item-key-2>"
uip or queue-items set-review-status Retried \
"<queue-item-key-1>" "<queue-item-key-2>"
set-review-status takes one of Retried, Abandoned, Deleted.
Triggers
List triggers in a folder
uip or triggers list --type time --folder-path Shared --enabled \
--output-filter "Data[].{name:name, cron:startProcessCron, enabled:isEnabled}"
uip or triggers list --type time --folder-path Shared --enabled \
--output-filter "Data[].{name:name, cron:startProcessCron, enabled:isEnabled}"
Three trigger types: time, queue, and api. Pass --type on every verb (it defaults to time). API triggers are tenant-scoped — omit --folder-path.
Create a time trigger
RELEASE_KEY=$(uip or processes list --folder-path Shared --name InvoiceProcessing \
--output-filter "Data[0].Key" --output plain)
uip or triggers create --type time \
--name NightlyInvoices \
--release-key "$RELEASE_KEY" \
--runtime-type Unattended \
--job-priority Normal \
--folder-path Shared \
--cron "0 0 2 * * ?" \
--time-zone UTC
RELEASE_KEY=$(uip or processes list --folder-path Shared --name InvoiceProcessing \
--output-filter "Data[0].Key" --output plain)
uip or triggers create --type time \
--name NightlyInvoices \
--release-key "$RELEASE_KEY" \
--runtime-type Unattended \
--job-priority Normal \
--folder-path Shared \
--cron "0 0 2 * * ?" \
--time-zone UTC
The --cron value uses Quartz's 6-field format (sec min hour dayOfMonth month dayOfWeek), not standard cron. "0 0 2 * * ?" is "every day at 02:00".
Enable or disable a trigger
There is no dedicated enable/disable command — toggle a trigger through update:
uip or triggers update <trigger-key> --type time --folder-path Shared --disabled
uip or triggers update <trigger-key> --type time --folder-path Shared --enabled
uip or triggers update <trigger-key> --type time --folder-path Shared --disabled
uip or triggers update <trigger-key> --type time --folder-path Shared --enabled
Use triggers history to diagnose a trigger that isn't firing — the fire log surfaces missing licenses, unavailable machines, and other upstream blocks.
Webhooks
Webhooks are tenant-scoped. Create once, and the webhook fires on every matching event in the tenant:
uip or webhooks create JobAlerts \
--url https://hooks.example.com/uipath \
--events "job.completed,job.faulted" \
--secret "$WEBHOOK_SECRET"
uip or webhooks create JobAlerts \
--url https://hooks.example.com/uipath \
--events "job.completed,job.faulted" \
--secret "$WEBHOOK_SECRET"
List available event types for a tenant:
uip or webhooks event-types
uip or webhooks event-types
Test delivery without waiting for a real event:
uip or webhooks ping <webhook-key>
uip or webhooks ping <webhook-key>
Libraries
Libraries are tenant-scoped (not folder-scoped) — they live in the tenant feed and are referenced by package IDs like MyLib:1.0.0:
# Upload a new version
uip or libraries upload --file ./MyLib.1.0.0.nupkg
# See all versions of a package
uip or libraries versions MyLib
# Download a specific version
uip or libraries download MyLib:1.0.0 --destination ./MyLib.1.0.0.nupkg
# Upload a new version
uip or libraries upload --file ./MyLib.1.0.0.nupkg
# See all versions of a package
uip or libraries versions MyLib
# Download a specific version
uip or libraries download MyLib:1.0.0 --destination ./MyLib.1.0.0.nupkg
Keys take the form PackageId:Version — not a GUID.
Scripting tips
- Always pass
--output-filterwhen feeding a single value into a variable. It avoids brittlejqinvocations and validates at CLI-parse time — see Scripting patterns. - List verbs return paginated results —
--limit/--offseton most,--continuation-tokenon bucket files. Empty results (zero rows inData) still exit0— the list query succeeded; nothing matched. - Most update/delete verbs are cross-folder — the flag table on each verb's section of
uip orsays so explicitly ("Cross-folder"). Onlycreateand list need the folder scope on those resources.
See also
uip orreference — the authoritative verb-by-verb flag list. Every snippet on this page links back to the matching section.uip solution deploy config link— bind a Solution's declared resource to one you created withuip or.- Scripting patterns — polling, retry on exit
2, idempotent pipelines. - How-to: pack and publish a Solution — the alternative path for resources that ship with a package.
- Conventions you need to know first
- Assets
- Bulk-deploy assets from a CSV
- Credential-type assets
- Sharing assets across folders
- Buckets and bucket files
- Upload a local file
- Download a file
- List and paginate
- Pre-signed URLs
- Queues and queue items
- Create a queue
- Add a single work item
- Bulk-add from a file
- Inspect failed items
- Mark failed items for retry
- Triggers
- List triggers in a folder
- Create a time trigger
- Enable or disable a trigger
- Webhooks
- Libraries
- Scripting tips
- See also